Solved

Citrix receiver PNAgent URL enumerates apps when not connected to domain, how?

Posted on 2014-10-14
6
627 Views
Last Modified: 2014-10-21
Hello there,

When I have my laptop connected to wifi network at home or in train during travel, the Citrix Receiver with server address pointing to https://mycompanyname/citrix/pnagent/citrix.xml, can enumerate apps and deskops, even though I am not connected to my company's network.

How is this possible? How is the communication happening?

Am I missing anything here, that I am not understanding.

Please advise.

Thanks and Regards
0
Comment
Question by:goprasad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 13

Expert Comment

by:Rizzle
ID: 40379536
Hi,

The applications may enumerating under a cached setting, what happens when you actually click on one?

I remember seeing this was once and the user could see their applications (Cached) but couldn't actually do anything with them.

Do you have Storefront in your environment?
0
 
LVL 13

Expert Comment

by:Rizzle
ID: 40379543
Unless the Citrix Receiver is pointing to the CAG in your environment?
0
 
LVL 23

Expert Comment

by:Dirk Kotte
ID: 40380844
is "mycompanyname" reacheble from the internet?
can you open https://mycompanyname/citrix/pnagent/citrix.xml within a browser and see  an XML output?

btw, the url should be the following:
https://mycompanyname/citrix/pnagent/config.xml
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 

Author Comment

by:goprasad
ID: 40383030
when i browse to mycompanyname in browser, I get an XML output.

And yes URL should end with config.xml
0
 
LVL 13

Expert Comment

by:Rizzle
ID: 40383036
You didn't answer my questions?
0
 
LVL 23

Accepted Solution

by:
Dirk Kotte earned 500 total points
ID: 40389759
Ok, seems you company publish the apps to the internet also.
There are different options how to accomplish this ... some secure , some not.
Your company may use a SSL gateway like CitrixAccessGateway (CAG), netscaler gateway or CitrixSecureGateway .
Also possible (but not secure) is to publish the webinterface-IIS directly using NAT at the firewall.

The first options are common and you should not  be surprised as a user.
if you are the responsible person for this environment or a security officer you should check this ;-)

and now the HOW:
your receiver connects to the published PNA-Site, receive the xml file you have seen already, send your authentication data (manually entered or from your session if pass-through is enabled) and the receiver gain access to your applications. Thats all.
0

Featured Post

ScreenConnect 6.0 Free Trial

Want empowering updates? You're in the right place! Discover new features in ScreenConnect 6.0, based on partner feedback, to keep you business operating smoothly and optimally (the way it should be). Explore all of the extras and enhancements for yourself!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
Giving access to ESXi shell console is always an issue for IT departments to other Teams, or Projects. We need to find a way so that teams can use ESXTOP for their POCs, or tests without giving them the access to ESXi host shell console with a root …
In this video tutorial I show you the main steps to install and configure  a VMware ESXi6.0 server. The video has my comments as text on the screen and you can pause anytime when needed. Hope this will be helpful. Verify that your hardware and BIO…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question